Security Software Engineer, IAM
New
V
VercelIdentity and access management
Remote - United StatesFull-TimeSenior
SalaryThe San Francisco, CA base pay range for this role is $208,000 - $312,000.
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years of experience in identity, access management, or platform security engineering
- Required Skills
- PythonOAuthGoRESTful APIsTerraform
Requirements
- Have 7+ years of experience in identity, access management, or platform security engineering.
- Have experience building internal tools or self-service platforms, rather than only administering existing products.
- Be proficient in a production language such as TypeScript/Node.js, Go, or Python.
- Be comfortable designing and consuming REST APIs and shipping and operating reliable services.
- Be proficient in Terraform and committed to managing IAM infrastructure as code; experience migrating existing systems is preferred.
- Have implementation-level experience with OAuth2, OIDC, SAML, and SCIM, including identity-related failure modes.
- Have experience designing IAM at scale across corporate environments, including Okta or an equivalent, and production environments using AWS or GCP IAM.
- Understand corporate IAM areas such as SSO, MFA, lifecycle management, and API-driven automation.
- Understand production IAM areas such as service accounts, roles, and workload identity federation.
- Be able to collaborate across Engineering, IT, Compliance, and Security teams.
- Be comfortable operating autonomously and owning decisions.
Responsibilities
- Own IAM strategy across corporate, production, and product environments, including the connection between corporate IAM and product and production IAM.
- Migrate Okta and related IAM configuration to Terraform so identity changes are reviewed, tested, and versioned.
- Build self-service access governance tooling, including just-in-time access, so team and system owners can define, request, and time-bound access.
- Own provisioning, deprovisioning, and access review workflows, with audit evidence generated by the system.
- Work with the Accounts team to identify how internal IAM connects with product IAM, including team and project roles, enterprise SSO, SCIM, and API tokens.
- Design and enforce least-privilege access controls across cloud, SaaS, and production infrastructure.
- Partner with platform and engineering teams to incorporate IAM during system design.
- Help define and build identity and access approaches for agents.
View Full Description & ApplyYou'll be redirected to the employer's site